MetaÒòÃ÷ÎÄ´æ´¢6ÒÚÓû§ÃÜÂë±»·£1ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2024-09-30
1. MetaÒòÃ÷ÎÄ´æ´¢6ÒÚÓû§ÃÜÂë±»·£1ÒÚÃÀÔª


9ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬°®¶ûÀ¼Êý¾Ý±£»£»£»£»£»£»£»¤Î¯Ô±»á£¨DPC£©¶ÔFacebookĸ¹«Ë¾Meta´¦ÒÔ9100ÍòÅ·Ôª£¨Ô¼1.01ÒÚÃÀÔª£©· £¿£¿£¿£¿î£¬£¬£¬ £¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇMetaÔÚ2019ÄêÒâÍ⽫6ÒÚÓû§µÄÃÜÂëÒÔÃ÷ÎÄÐÎʽ´æ´¢¡£¡£¡£ ¡£¡£¡£ÕâÒ»´¦·ÖÔ´ÓÚÒ»ÆðÒ»Á¬5ÄêµÄÊӲ졣¡£¡£ ¡£¡£¡£2019Äê3Ô£¬£¬£¬ £¬£¬£¬Çå¾²Ñо¿Ô±²¼Àµ¶÷¡¤¿ËÀײ¼Ë¹·¢Ã÷MetaÓû§ÃÜÂëÇ徲ȱÏÝ£¬£¬£¬ £¬£¬£¬MetaËæºóÈ·Èϲ¢ÔÚÄÚ²¿ÏµÍ³ÉÏ·¢Ã÷δ¼ÓÃܵÄÓû§ÃÜÂ룬£¬£¬ £¬£¬£¬²¢ÏòDPCת´ï£¬£¬£¬ £¬£¬£¬Í¬Ê±Ç¿µ÷ûÓÐÖ¤¾ÝÅú×¢ÃÜÂë±»ÀÄÓ㬣¬£¬ £¬£¬£¬²¢Á¬Ã¦ÐÞ¸´Á˸ùýʧ¡£¡£¡£ ¡£¡£¡£È»¶ø£¬£¬£¬ £¬£¬£¬DPCÈ϶¨MetaÎ¥·´ÁË¡¶Í¨ÓÃÊý¾Ý±£»£»£»£»£»£»£»¤ÌõÀý¡·£¨GDPR£©ÖеĶàÏîÇå¾²ÒªÇ󣬣¬£¬ £¬£¬£¬°üÀ¨Î´ÄÜ֪ͨºÍ¼Í¼Êý¾Ýй¶£¬£¬£¬ £¬£¬£¬Î´Ê¹ÓÃÊʵ±µÄÊÖÒÕ»ò×éÖ¯²½·¥È·±£Óû§ÃÜÂëÇå¾²£¬£¬£¬ £¬£¬£¬ÒÔ¼°Î´ÊµÑéÊʵ±µÄÇå¾²²½·¥È·±£Óû§ÃÜÂëÒ»Á¬ÉñÃØÐÔ¡£¡£¡£ ¡£¡£¡£DPC¸±×¨Ô±¸ñÀ×¶òÄ·¡¤¶àÒÁ¶ûÌåÏÖ£¬£¬£¬ £¬£¬£¬Óû§ÃÜÂë²»Ó¦ÒÔÃ÷ÎÄÐÎʽ´æ´¢£¬£¬£¬ £¬£¬£¬Ë¼Á¿µ½»á¼û´ËÀàÊý¾ÝµÄÈË¿ÉÄÜ´øÀ´µÄÀÄÓÃΣº¦¡£¡£¡£ ¡£¡£¡£ËäÈ»×î³õµÄ±¬ÁÏÕß¿ËÀײ¼Ë¹Ã»Óз¢Ã÷FacebookÔ±¹¤Æäʱ»á¼ûÁ˱»ÆØ¹âÃÜÂëµÄÖ¤¾Ý£¬£¬£¬ £¬£¬£¬µ«Ç徲ȱÏÝ¿ÉÄÜÈÃFacebookµÄ20ÍòÔ±¹¤ÖеÄÈκÎÒ»ÈË¿´µ½Õâ¶à´ï6ÒÚ¸öÕË»§µÄÃ÷ÎÄÃÜÂë¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Meta½üÆÚÒò¶à´ÎÎ¥·´GDPR»®¶¨¶ø±»· £¿£¿£¿£¿î£¬£¬£¬ £¬£¬£¬°üÀ¨Êý¾Ýץȡй¶¡¢Óû§Ô޳ɺÍÊý¾Ý´¦Öóͷ£Î¥¹æ£¬£¬£¬ £¬£¬£¬ÒÔ¼°ÏòÃÀ¹ú´«ÊäСÎÒ˽¼ÒÊý¾ÝµÄ·½·¨µÈ£¬£¬£¬ £¬£¬£¬ÆäÖÐ×î´óµÄÒ»±Ê· £¿£¿£¿£¿î¸ß´ï12ÒÚÅ·Ôª¡£¡£¡£ ¡£¡£¡£MetaÕýÔÚ¶ÔDPCµÄѶ¶ÏÌá³öÉÏËß¡£¡£¡£ ¡£¡£¡£


https://cybernews.com/security/meta-100m-fine-dpc-ireland-plaintext-passwords-facebook-leak/


2. NVIDIA Container ToolkitÑÏÖØÎó²îÓ°ÏìAIÓ¦ÓÃÇå¾²


9ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬NVIDIA Container ToolkitÖб£´æÒ»¸ö±»×·×ÙΪCVE-2024-0132µÄÑÏÖØÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßÖ´ÐÐÈÝÆ÷ÌÓÒݹ¥»÷²¢»ñµÃ¶ÔÖ÷»úϵͳµÄÍêÈ«»á¼ûȨÏÞ£¬£¬£¬ £¬£¬£¬´Ó¶øÖ´ÐÐÏÂÁî»òй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÓ°ÏìNVIDIA Container Toolkit 1.16.1¼°¸üÔç°æ±¾ÒÔ¼°GPU Operator 24.6.1¼°¸üÔç°æ±¾£¬£¬£¬ £¬£¬£¬²¢ÇÒÓÉÓڸÿâԤװÔÚÐí¶àÒÔAIΪÖÐÐĵį½Ì¨ºÍÐéÄâ»úÓ³ÏñÖУ¬£¬£¬ £¬£¬£¬Áè¼Ý35%µÄÔÆÇéÐÎÃæÁÙʹÓøÃÎó²î¾ÙÐй¥»÷µÄΣº¦¡£¡£¡£ ¡£¡£¡£ÎÊÌâÔÚÓÚÈÝÆ÷»¯µÄGPUÓëÖ÷»úÖ®¼äȱ·¦Çå¾²¸ôÀ룬£¬£¬ £¬£¬£¬ÔÊÐíÈÝÆ÷¹ÒÔØÖ÷»úÎļþϵͳµÄÃô¸Ð²¿·Ö»ò»á¼ûÔËÐÐʱ×ÊÔ´¡£¡£¡£ ¡£¡£¡£WizÑо¿Ö°Ô±·¢Ã÷Á˸ÃÎó²î£¬£¬£¬ £¬£¬£¬²¢ÓÚ9ÔÂ1ÈÕÏòNVIDIA±¨¸æ£¬£¬£¬ £¬£¬£¬NVIDIAÓÚ9ÔÂ26ÈÕÐû²¼ÁËÐÞ¸´³ÌÐò¡£¡£¡£ ¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§Éý¼¶µ½NVIDIA Container Toolkit°æ±¾1.16.2ºÍNVIDIA GPU Operator 24.6.2¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬Ê¹ÓøÃÎó²îµÄÊÖÒÕϸ½ÚÈÔ´¦ÓÚ±£ÃÜ״̬£¬£¬£¬ £¬£¬£¬ÒÔ±ãÊÜÓ°ÏìµÄ×éÖ¯ÓÐʱ¼äÔÚÆäÇéÐÎÖлº½â¸ÃÎÊÌâ¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/critical-flaw-in-nvidia-container-toolkit-allows-full-host-takeover/


3. °ÍÎ÷ÔâÖØ´ó¶ñÒâÈí¼þѬȾÁ´¹¥»÷£¬£¬£¬ £¬£¬£¬Éæ¼°BBTokÒøÐÐľÂí


9ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬G DATA CyberDefense×î½ü·¢Ã÷ÁËÒ»ÏîÕë¶Ô°ÍÎ÷ʵÌåµÄÖØ´ó¶ñÒâÈí¼þѬȾÁ´£¬£¬£¬ £¬£¬£¬¸ÃѬȾÁ´ÓëBBTokÒøÐÐľÂíÓйأ¬£¬£¬ £¬£¬£¬½ÓÄɶà½×¶ÎÒªÁì¡£¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ý´¹ÂÚµç×ÓÓʼþ·¢ËÍαװ³É°ÍÎ÷³£ÓÃÊý×Ö·¢Æ±µÄ¶ñÒâISOÓ³Ïñ£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§Ö´ÐжñÒâ¸ºÔØ¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓÃMicrosoft Build Engine±àÒë¶ñÒâC#´úÂ룬£¬£¬ £¬£¬£¬²¢Ê¹ÓÃAppDomain Manager×¢ÈëÊÖÒÕʵÏָ߼¶Ö´ÐУ¬£¬£¬ £¬£¬£¬Í¬Ê±½ÓÄÉConfuserEx±äÌå»ìÏý.NET¼ÓÔØ³ÌÐòÒÔÌӱܼì²â¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬¶ñÒâÈí¼þ»¹°üÀ¨¶àÖÖ³¤ÆÚÐÔ»úÖÆ£¬£¬£¬ £¬£¬£¬²¢ÊµÑé½ûÓÃÇå¾²¹¤¾ß¡£¡£¡£ ¡£¡£¡£Ñ¬È¾Á´ÖÐʹÓÃÕýµ±ÊðÀíЧÀÍÆ÷Ó¦ÓóÌÐòCCProxyαװ³ÉÕýµ±µÄÍøÂçÀú³Ì£¬£¬£¬ £¬£¬£¬Ôö½øÓëÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷µÄͨѶ¡£¡£¡£ ¡£¡£¡£½¨ÒéÆóҵʵÑéÑÏ¿áµÄµç×ÓÓʼþ¹ýÂË¡¢°´ÆÚ¸üÐÂÈí¼þ¡¢°²ÅŸ߼¶¶Ëµã±£»£»£»£»£»£»£»¤£¬£¬£¬ £¬£¬£¬²¢½ÌÓýÔ±¹¤Ïàʶ´¹ÂÚµç×ÓÓʼþµÄΣÏÕ£¬£¬£¬ £¬£¬£¬ÒÔ¼õÇá´ËÀà¸ß¼¶ÒøÐÐľÂí´øÀ´µÄΣº¦¡£¡£¡£ ¡£¡£¡£


https://securityonline.info/net-loaders-and-stealthy-persistence-bbtok-trojans-new-tricks/


4. GiveWP¾èÔù²å¼þ·¢Ã÷ÑÏÖØÎó²î£¬£¬£¬ £¬£¬£¬10Íò¸öWordPressÍøÕ¾ÃæÁÙΣº¦


9ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬ÔÚÊ¢ÐÐµÄ WordPress GiveWP ¾èÔù²å¼þÖз¢Ã÷ÁËÒ»¸öÑÏÖØÎó²îCVE-2024-8353£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚPHP¹¤¾ß×¢È룬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬ £¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄÍøÕ¾¡£¡£¡£ ¡£¡£¡£Îó²î×î¸ßÑÏÖØÐÔÆÀ·ÖΪ10£¬£¬£¬ £¬£¬£¬ÓÉÓÚ´¦Öóͷ£²»ÊÜÐÅÈεÄÊäÈë²»µ±£¬£¬£¬ £¬£¬£¬ÌØÊâÊÇÔÚ·´ÐòÁл¯¶à¸ö²ÎÊýʱ´ú±¬·¢¡£¡£¡£ ¡£¡£¡£Ö»¹ÜÔÚ°æ±¾3.16.1ÖÐÒѲ¿·ÖÐÞ²¹£¬£¬£¬ £¬£¬£¬µ«ËùÓа汾µÄGiveWP£¨°üÀ¨3.16.1£©¶¼±£´æ´ËÎó²î£¬£¬£¬ £¬£¬£¬¸Ã²å¼þÏÖÔÚÒÑ×°ÖÃÁè¼Ý10Íò´Î£¬£¬£¬ £¬£¬£¬¶Ô´ó×ÚÒÀÀµ¸Ã²å¼þµÄWordPressÍøÕ¾×é³ÉÖØ´óÇ徲Σº¦¡£¡£¡£ ¡£¡£¡£Òò´Ë£¬£¬£¬ £¬£¬£¬Á¬Ã¦½«GiveWP¸üÐÂÖÁ3.16.2»ò¸ü¸ß°æ±¾ÖÁ¹ØÖ÷Òª£¬£¬£¬ £¬£¬£¬Í¬Ê±ÍøÕ¾ÖÎÀíÔ±Ó¦¼à¿ØÈÕÖ¾ÖÐÊÇ·ñ±£´æ¿ÉÒɻ£¬£¬£¬ £¬£¬£¬²¢Ë¼Á¿½ÓÄÉÌØÁíÍâÇå¾²²ãÒÔ½µµÍδÀ´Îó²îµÄΣº¦¡£¡£¡£ ¡£¡£¡£


https://securityonline.info/cve-2024-8353-critical-givewp-flaw-100k-wordpress-sites-at-risk/


5. KimsukyʹÓÃжñÒâÈí¼þKLogEXEºÍFPSpy¾ÙÐÐÍøÂçÌØ¹¤»î¶¯


9ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬Unit 42 Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ £¬£¬£¬ÎÛÃûÕÑÖøµÄ³¯Ïʸ߼¶Ò»Á¬ÐÔÍþв×éÖ¯ Sparkling Pisces£¨ÓÖÃû Kimsuky£©ÕýÔÚʹÓÃÁ½¿îеĶñÒâÈí¼þÑù±¾£ºÎ´¼Í¼µÄ¼üÅ̼ͼÆ÷ KLogEXE ºÍºóÃűäÖÖ FPSpy£¬£¬£¬ £¬£¬£¬½øÒ»²½À©Õ¹Æä¹¤¾ß°üºÍ¹¦Ð§¡£¡£¡£ ¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ±»ÓÃÓÚÕë¶Ôº«¹ú¡¢ÈÕ±¾µÈ¹ú¼ÒµÄÒªº¦²¿·ÖµÄÍøÂçÌØ¹¤»î¶¯¡£¡£¡£ ¡£¡£¡£KLogEXE Äܹ»¼à¿ØÊܺ¦ÕߵļüÅÌÊäÈëºÍÊó±êµã»÷£¬£¬£¬ £¬£¬£¬ÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬²¢Í¨¹ý HTTP ·¢Ë͵½ Sparkling Pisces µÄÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£ ¡£¡£¡£ËüʹÓà HackingTeam й¶µÄ´úÂë»ìÏý API ŲÓ㬣¬£¬ £¬£¬£¬ÒÔÈÆ¹ý¾²Ì¬¼ì²âÒªÁì¡£¡£¡£ ¡£¡£¡£FPSpy ÔòÊÇ»ùÓÚ Sparkling Pisces ֮ǰµÄ¶ñÒâÈí¼þ»î¶¯µÄ¸ß¼¶ºóÃÅ£¬£¬£¬ £¬£¬£¬ÌṩÁ˳ý¼üÅ̼ͼ֮ÍâµÄһϵÁй¦Ð§£¬£¬£¬ £¬£¬£¬°üÀ¨Êý¾ÝÍøÂç¡¢Ö´ÐÐí§ÒâÏÂÁîºÍÏÂÔØÆäËû¼ÓÃÜÄ £¿£¿£¿£¿é¡£¡£¡£ ¡£¡£¡£Á½¿î¶ñÒâÈí¼þÖ®¼ä±£´æ´ó×Ú»ù´¡ÉèÊ©ÖØµþ£¬£¬£¬ £¬£¬£¬¹²ÏíÏàͬµÄ C2 »ù´¡ÉèÊ©ºÍ´úÂë¿â£¬£¬£¬ £¬£¬£¬Åú×¢ËüÃǶ¼ÊÇ Sparkling Pisces Эͬ»î¶¯µÄÒ»²¿·Ö¡£¡£¡£ ¡£¡£¡£Sparkling Pisces µÄ»ù´¡ÉèÊ©ÖØ´óÇÒ˳ӦÐÔÇ¿£¬£¬£¬ £¬£¬£¬Ê¹Çå¾²ÍŶÓÄÑÒÔ×·×ÙÆä»î¶¯¡£¡£¡£ ¡£¡£¡£


https://securityonline.info/klogexe-fpspy-kimsukys-evolving-cyber-espionage-arsenal/


6. ð³äÓ¢ÐÛͬÃËÏÂÔØ¹ã¸æÈö²¥Lumma Stealer¶ñÒâÈí¼þ


9ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬Ëæ×ÅÓ¢ÐÛͬÃË£¨LoL£©È«Çò×ܾöÈüµÄÈȶÈÒ»Ö±ÅÊÉý£¬£¬£¬ £¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÕýʹÓÃÕâһʱ»ú£¬£¬£¬ £¬£¬£¬Í¨¹ý¶ñÒâÈí¼þ»î¶¯¶ÔÓÎÏ··ÛË¿Óû§ÊµÑé¹¥»÷¡£¡£¡£ ¡£¡£¡£¾ÝBitdefender Labs×î½ü±¨¸æ£¬£¬£¬ £¬£¬£¬Ò»ÖÖÕë¶ÔÅ·ÖÞÍæ¼ÒµÄÐÂÐÍÍøÂçÍþвÒѵ¼ÖÂÔ¼4000ÃûÊܺ¦Õߣ¬£¬£¬ £¬£¬£¬ÆäÖжàΪ³ÉÄêÄÐÐÔ¡£¡£¡£ ¡£¡£¡£ÕâÖÖ¶ñÒâ»î¶¯Í¨¹ýÈ«ÐÄÉè¼ÆµÄÉ罻ýÌåÓÎÏ·¹ã¸æ£¬£¬£¬ £¬£¬£¬ÓÕµ¼·ÛË¿ÏÂÔØ¿´ËÆÕýµ±µÄÓ¢ÐÛͬÃËÓÎÏ·£¬£¬£¬ £¬£¬£¬ÊµÔò×°ÖÃÁËLumma Stealer¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¡£¸ÃÈí¼þÄܹ»ÇÔÊØÐÅÓÿ¨ÐÅÏ¢¡¢ÃÜÂë¡¢¼ÓÃÜÇ®°ü¼°ä¯ÀÀÆ÷»á»°cookieµÈÃô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£Êܺ¦Õ߻ᱻָµ¼ÖÁÒ»¸öÄ£Äâ¾É°æÓ¢ÐÛͬÃËÏÂÔØÒ³ÃæµÄÍøÕ¾£¬£¬£¬ £¬£¬£¬¸ÃÒ³Ãæ½ÓÄÉ´í±ð×ÖÇÀ×¢ÊÖÒÕ£¬£¬£¬ £¬£¬£¬ÔöÌíÁ˼ì²âÄѶÈ¡£¡£¡£ ¡£¡£¡£Ò»µ©µã»÷ÏÂÔØÁ´½Ó£¬£¬£¬ £¬£¬£¬Êܺ¦Õß½«±»Öض¨ÏòÖÁ°üÀ¨¶ñÒâ´æµµµÄBitbucket´æ´¢¿â£¬£¬£¬ £¬£¬£¬ÏÂÔØµÄѹËõ°üÖаüÀ¨Lumma StealerµÄÏÂÔØÆ÷¡£¡£¡£ ¡£¡£¡£Lumma Stealer¹¦Ð§Ç¿Ê¢£¬£¬£¬ £¬£¬£¬Äܽ«×ÔÉí×¢ÈëÕýµ±µÄWindowsÀú³ÌÒÔÌӱܼì²â£¬£¬£¬ £¬£¬£¬²¢½«ÇÔÈ¡µÄÊý¾ÝÔÚµØÏÂÊг¡³öÊÛ£¬£¬£¬ £¬£¬£¬½ø¶øÔö½øÉí·Ý͵ÇÔºÍÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£ ¡£¡£¡£Ç徲ר¼ÒÌáÐÑÓû§£¬£¬£¬ £¬£¬£¬ÔÚÏÂÔØÓÎϷʱÎñ±Ø×Ðϸ¼ì²éÍøÕ¾URL£¬£¬£¬ £¬£¬£¬½¨Òé´Ó¹Ù·½ÇþµÀÏÂÔØ£¬£¬£¬ £¬£¬£¬²¢Ð¡ÐĹýÓÚÓÕÈ˵ÄÔÚÏß¹ã¸æ£¬£¬£¬ £¬£¬£¬ÒÔ±£»£»£»£»£»£»£»¤×Ô¼ºµÄСÎÒ˽¼ÒÐÅÏ¢Çå¾²¡£¡£¡£ ¡£¡£¡£


https://hackread.com/fake-league-of-legends-download-ads-lumma-stealer/#google_vignette